news.mlab.sh
Back to the feed
vulnerability

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

Critical
Image: The Hacker News
Summary

CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP code execution, and there is currently no public information on active exploitation. Federal Civilian Executive Branch (FCEB) agencies are being directed to apply the patch immediately.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.